CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-10057
4.8 MEDIUM

ITS Intelligent SCADA System developed by ITP Technology has a Stored Cross-Site Scripting vulnerability, allowing privileged remote attackers to inject persistent JavaScript codes that are …

May 29, 2026
CVE-2026-10052
4.1 MEDIUM

A flaw was found in the Quay config-tool's LDAP and SMTP validation functions. An attacker with config editor access can exploit these functions, which make …

May 29, 2026
CVE-2026-10039
4.9 MEDIUM

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to generic SQL Injection via the 'order' parameter in all versions up to, and including, …

May 29, 2026
CVE-2026-9243
6.4 MEDIUM

The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'carousel_direction' parameter of the Carousel Anything widget in versions …

May 29, 2026
CVE-2026-49322
4.3 MEDIUM

Weak authentication in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with read …

May 29, 2026
CVE-2026-9714
6.4 MEDIUM

The Simple Divi Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the [showmodule] shortcode in versions up to, …

May 29, 2026
CVE-2026-9493
6.5 MEDIUM

Service Center developed by BankPro E-Service Technology has an Insecure Direct Object Reference vulnerability, allowing authenticated remote attackers to modify the parameter of a specific …

May 29, 2026
CVE-2026-6324
4.8 MEDIUM

A flaw was found in libsoup. A remote attacker could exploit an unsigned to signed conversion error in the `soup_body_input_stream_read_chunked()` function by sending a malicious …

May 29, 2026
CVE-2026-6275
6.4 MEDIUM

The StatCounter – Free Real Time Visitor Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.1 This …

May 29, 2026
CVE-2025-14042
6.4 MEDIUM

The Automotive Car Dealership Business WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Project Details' custom field in Portfolio Items in …

May 29, 2026
CVE-2026-2128
5.3 MEDIUM

The Breeze plugin for WordPress is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in all versions up to, and including, 2.5.2 This …

May 29, 2026
CVE-2026-8995
4.3 MEDIUM

The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including …

May 29, 2026
CVE-2026-7430
4.4 MEDIUM

The Post Snippets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.0.19. This is due to insufficient …

May 29, 2026
CVE-2026-6892
5.0 MEDIUM

Improper handling of symbolic links in the installer of CUPS Printer Driver for macOS(*) may allow a local attacker with login privileges to exploit a …

May 29, 2026
CVE-2026-6891
5.0 MEDIUM

Improper handling of symbolic links in the installer of My Image Garden for macOS Version 3.6.8 or earlier may allow a local attacker with login …

May 29, 2026
CVE-2026-9996
6.5 MEDIUM

Out of bounds read in WebRTC in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process …

May 28, 2026
CVE-2026-9989
6.3 MEDIUM

Inappropriate implementation in Media in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to bypass same origin policy via a crafted video file. (Chromium …

May 28, 2026
CVE-2026-9986
4.2 MEDIUM

Insufficient validation of untrusted input in OptimizationGuide in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to perform …

May 28, 2026
CVE-2026-9985
5.3 MEDIUM

Insufficient validation of untrusted input in Media in Google Chrome on ChromeOS prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process …

May 28, 2026
CVE-2026-9981
6.5 MEDIUM

Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted …

May 28, 2026
CVE-2026-9980
5.0 MEDIUM

Insufficient validation of untrusted input in Printing in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass …

May 28, 2026
CVE-2026-9979
5.0 MEDIUM

Insufficient validation of untrusted input in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass …

May 28, 2026
CVE-2026-9971
5.4 MEDIUM

Inappropriate implementation in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI …

May 28, 2026
CVE-2026-9955
4.3 MEDIUM

Inappropriate implementation in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. …

May 28, 2026
CVE-2026-9953
6.5 MEDIUM

Out of bounds read in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via …

May 28, 2026
CVE-2026-9943
4.3 MEDIUM

Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted …

May 28, 2026
CVE-2026-9942
5.0 MEDIUM

Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass site isolation via …

May 28, 2026
CVE-2026-9935
4.3 MEDIUM

Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security …

May 28, 2026
CVE-2026-9930
4.3 MEDIUM

Out of bounds write in Dawn in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to perform an out of bounds memory …

May 28, 2026
CVE-2026-9929
4.3 MEDIUM

Inappropriate implementation in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. …

May 28, 2026
CVE-2026-9921
4.3 MEDIUM

Uninitialized Use in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin information via a crafted HTML page. …

May 28, 2026
CVE-2026-9919
4.3 MEDIUM

Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted …

May 28, 2026
CVE-2026-9917
6.5 MEDIUM

Uninitialized Use in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via …

May 28, 2026
CVE-2026-9913
4.3 MEDIUM

Inappropriate implementation in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform out of bounds memory access via a crafted …

May 28, 2026
CVE-2026-9912
6.5 MEDIUM

Inappropriate implementation in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via …

May 28, 2026
CVE-2026-9911
4.3 MEDIUM

Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to perform an out of bounds memory read via a crafted …

May 28, 2026
CVE-2026-9908
6.5 MEDIUM

Out of bounds read in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via …

May 28, 2026
CVE-2026-9907
4.3 MEDIUM

Out of bounds read in Dawn in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted …

May 28, 2026
CVE-2026-9903
5.0 MEDIUM

Insufficient validation of untrusted input in Site Isolation in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to …

May 28, 2026
CVE-2026-9882
6.5 MEDIUM

Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security …

May 28, 2026
CVE-2026-10028
4.3 MEDIUM

A flaw was found in glib-networking. A remote attacker can exploit this vulnerability by presenting a specially crafted certificate chain to an application that uses …

May 28, 2026
CVE-2026-10018
6.5 MEDIUM

Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted …

May 28, 2026
CVE-2026-10010
5.0 MEDIUM

Inappropriate implementation in Input in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass site …

May 28, 2026
CVE-2026-10008
6.5 MEDIUM

Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via …

May 28, 2026
CVE-2026-10004
6.5 MEDIUM

Insufficient validation of untrusted input in Passwords in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to perform UI spoofing via a crafted HTML …

May 28, 2026
CVE-2026-45410
5.3 MEDIUM

TREK is a collaborative travel planner. Prior to 3.0.18, early return on missing user during login flow allowed an attacker to enumerate valid user accounts …

May 28, 2026
CVE-2026-45366
4.7 MEDIUM

typescript-utcp is a typescript implementation of UTCP. Prior to 1.1.2, the @utcp/http package is vulnerable to a blind Server-Side Request Forgery (SSRF) caused by a …

May 28, 2026
CVE-2026-45023
5.4 MEDIUM

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.59, POST /api/blocks/{block_id}/execute endpoint executes blocks without consuming …

May 28, 2026
CVE-2026-44885
5.5 MEDIUM

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From …

May 28, 2026
CVE-2026-44884
6.5 MEDIUM

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From …

May 28, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.